TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Team Up to Attack Microsoft SharePoint Systems

Akinola Ajibola by Akinola Ajibola
August 4, 2025
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • A Microsoft SharePoint vulnerability chain has been the focus of continuing attacks by cybercriminals who has teamed up to be a ransomware gangs.
  • This is part of a larger exploitation effort that has already resulted in the penetration of at least 148 organisations globally.
  • A 4L4MD4R ransomware variant, based on open-source Mauri870 code, was found by security researchers at Palo Alto Networks’ Unit 42 while investigating events employing this SharePoint...

A Microsoft SharePoint vulnerability chain has been the focus of continuing attacks by cybercriminals who has teamed up to be a ransomware gangs. This is part of a larger exploitation effort that has already resulted in the penetration of at least 148 organisations globally.

A 4L4MD4R ransomware variant, based on open-source Mauri870 code, was found by security researchers at Palo Alto Networks’ Unit 42 while investigating events employing this SharePoint exploit chain (named “ToolShell”).

After identifying a trojan loader that downloads and runs the ransomware from theinnovationfactory[.]it (145.239.97[.]206), the ransomware was identified on July 27.

After a failed effort at exploitation that exposed malicious PowerShell commands intended to turn off security monitoring on the targeted device, the loader was discovered.

“The 4L4MD4R payload was found to be GoLang-written and UPX-packed on analysis. When the sample is executed, it loads memory to load the decrypted PE file, decrypts an AES-encrypted payload in memory, and starts a new thread to run it,” Unit 42 stated.

The 4L4MD4R ransomware creates ransom notes and encrypted file lists on hacked computers, encrypts files on the compromised system, and wants 0.005 Bitcoin in payment.

Google and Microsoft have also connected Chinese threat actors to the ToolShell attacks; according to Microsoft security experts, three distinct state-sponsored hacker organizations which are Linen Typhoon, Violet Typhoon, and Storm-2603 are involved.

Also worth reading
Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand OpenAI Says Its Test Models Breached Hugging Face During Cyber Evaluation South Africa Wants SIM Cards To Become Trusted Digital IDs Kenya Restores President Ruto Website After Bitcoin Ransom Hack Hugging Face Says An Agentic AI System Hacked Its Data Pipeline Context Bombing Turns Prompt Injection Into A Defence Against AI Hackers

This campaign has so far compromised a number of high-profile targets, including as the Department of Education, the U.S. National Nuclear Security Administration, the Department of Revenue in Florida, the General Assembly of Rhode Island, and government networks in Europe and the Middle East.

“Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers,” stated Microsoft. Furthermore, we have seen that Storm-2603, a threat actor based in China, is taking advantage of these weaknesses. The use of these exploits by other actors is still being investigated.

ToolShell exploitation targeting CVE-2025-49706 and CVE-2025-49704 was first discovered by Dutch cybersecurity firm Eye Security in zero-day assaults, initially identifying 54 vulnerable organisations, including government agencies and international corporations. Check Point Research later discovered evidence of exploitation that dates back to 7 July and targets technology, telecommunications, and government organisations in Western Europe and North America.

In addition to assigning two new CVE IDs (CVE-2025-53770 and CVE-2025-53771) for zero-days used to compromise fully patched SharePoint servers, Microsoft fixed the two vulnerabilities in the July 2025 Patch Tuesday releases.

The actual scope goes far beyond initial estimates, according to Eye Security Chief Technology Officer Piet Kerkhofs, who told a media agency that the attackers have infected at least 400 servers with malware across the networks of at least 148 organisations, many of which have been compromised for extended periods of time.

In addition to ordering government agencies to secure their systems within 24 hours, the Cybersecurity and Infrastructure Security Agency (CISA) has added the ToolShell exploit chain’s CVE-2025-53770 remote code execution vulnerability to its list of exploited vulnerabilities.

This comes at a time when Heimdal Security shared some safety advised on SharePoint zero-day (CVE-2025-53770) under active exploitation.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • 5cdb1bc21ea851eb0c74bf693121f711
    Chinese Hackers Exploiting SharePoint Zero-day - Microsoft
  • 4025691-0-97050800-1753099410-original
    Microsoft Patches SharePoint Bug, Leaves 2016…
  • microsoft-sharepoint-104_v-variantBig1x1_w-1280_zc-3061602c
    SharePoint Zero-day Persists Despite Microsoft Patches
  • GettyImages-1561639950
    JadePuffer: The First Fully AI-Powered Ransomware…
  • 960x0 (1)
    Medusa Ransomware Targets Over 200 Gmail Users
  • GettyImages-2175312180
    UK Outlaws Ransomware Payments by Government Agencies
  • Advantest_rushes_to_boost_AI_chip_tester_Bloomberg_20260128185756_Bloomberg
    Chip Tester Advantest Struck By Ransomware
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: cybersecuritymicrosoft sharepointsharepoint
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Claude Opus 5 Gives Anthropic A Cheaper Answer To The Fable 5 Problem July 25, 2026
  • Meta Makes Facebook Verified Free As AI Scams Make Real People Harder To Spot July 24, 2026
  • SAP Cloud Growth Eases Fears That AI Will Weaken Enterprise Software July 24, 2026
  • US Lawmakers Push AI Kill Switch Bill After OpenAI Rogue-Model Incident July 24, 2026
  • Airtel Money’s $61B Quarter Makes Its London IPO A Bigger Africa Fintech Story July 24, 2026
  • Intel Q2 Revenue Jumps As AI Compute Demand Lifts Chip Business July 24, 2026
  • AMD And Anthropic Deal Puts Real Pressure On Nvidia’s AI Chip Lead July 24, 2026
  • New York’s Data Centre Pause Shows AI Infrastructure Is Hitting Politics July 23, 2026
  • OpenAI Researcher’s $2B Drug Discovery Plan Shows AI Biotech Hype Is Back July 23, 2026
  • Airtel Africa Q1 Shows Mobile Money And Data Are Doing The Heavy Lifting July 23, 2026
  • ZainTECH And Nile Build AI-Ready Networks For Enterprises July 23, 2026
  • Google Cloud Boom Makes Alphabet AI Spending Look More Real July 23, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.